← WordPress Vulnerabilities
WordPress security by component

Database Backup for WordPress

Database Backup for WordPress is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published May 14, 2026; the highest CVE/CNA score is 8.1.

Plugin slug: wp-db-backup

CVE-2026-4031: Database Backup for WordPress: Sensitive information exposure

Database Backup for WordPress is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The published affected range is <= 2.5.2.

PublishedMay 14, 2026
Known safe version> 2.5.2
Safe version
May 14, 2026 CVE-2026-4031
Database Backup for WordPress: Sensitive information exposure
Database Backup for WordPress is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The published affected range is <= 2.5.2.
> 2.5.2
CVE7.5
NVDPending
May 14, 2026 CVE-2026-4030
Database Backup for WordPress: Filesystem traversal
Database Backup for WordPress is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 2.5.2.
> 2.5.2
CVE8.1
NVDPending
May 14, 2026 CVE-2026-4029
Database Backup for WordPress: Sensitive information exposure
Database Backup for WordPress is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The published affected range is <= 2.5.2.
> 2.5.2
CVE7.5
NVDPending
Oct 05, 2018 CVE-2014-10076
Wp Db Backup: A security weakness
Wp Db Backup is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5